This file documents all important changes. Please document all
important changes in this file and not only write a comment during
"cvs commit".

2004-Sep-03:
	* 0.9.1.9
	* fixed Cross-Site-Scripting vulnerability (CAN-2004-0787)
	* Patched bpRevokeCertificate with NOCHAIN to fix role verification problem.
	* added missing path $common_libs to initRBAC
2004-Feb-19
	* 0.9.1.8
	* fixed reversed subjects after recovery of OpenSSL's index.txt
	* better errormessage for send_cert_key_pkcs12 if the passphrase is
	  wrong (doesn't corrupt openca.pot)
	* fix for CRIN supported by the user during CSR generation
2004-Jan-15
	* 0.9.1.7
	* the correct certificate in a chain must be located via a complete
	  comparison and not only a serial match in crypto-utils.lib
	  (security advisory CAN-2004-0004 issued)
2003-Dec-19:
	* 0.9.1.6
	* fixed LDAP code to support certificates without an emailaddress
2003-Dec-10:
	* 0.9.1.5
	* moved PEMCACert to CACertificate
	* CACertificate always cacert.pem
	* removed illegal configure file from it_IT
2003-Nov-27:
	* 0.9.1.4
	* fixed errormessage if the loading of code fails from Ronny Standtke
	  <standtke@swiss-it.ch>
	* fixed importCACert to support CA hierarchies
	* fixed infinite loop in bpApprovePendingCSR
	* better errormessage for empty database passphrases
	* fixed three bugs in crypto-utils.lib and OpenCA::PKCS7 which corrupt
	  the signature verification - the serial of a CA certificate was
	  sometimes used to load and check the certificate which was used to
	  sign the data (security advisory CAN-2003-0960 issued)
	* verifySignature and viewSignature include the same bugs like
	  crypto-utils.lib
	* fixed signature verification of role in sub CAs in bpIssueCertificate
	  and OpenCA::PKCS7
2003-Aug-20:
	* 0.9.1.3
	* fixed empty states during dataexchange of objects in export-import.lib
	* fix CA certificate handling in OpenCA::DBI
	* added support for mailaddresses in ldap-utils.lib for every possible
	  objectclass
	* replaced most tests -f in makefiles with -e
	* backported makefile in src/modules to detect already existing modules
	* SECURITY BUGFIX: configurationfiles of the servers has now permission
	  640, owner openca_user and group httpd_group to protect the private
	  content like ldap passphrases
2003-Jul-01:
	* 0.9.1.2
2003-Jun-11:
	* third pre-release of 0.9.1.2 and snapshot of CVS HEAD
	* fixed lost datatype in removeKey from Venki
	  <a_venkatesh79@yahoo.co.uk>
	* fixed conversion of CA-cert in genCACert from PEM to TXT (found by
	  Stefan Dietiker <dietiste@zhwin.ch>)
	* ldap fixes in ldap-utils.lib:
	    - wrong regex which creates wrong attribute values for the suffix
	    - wrong LDAP objectclass stacks
	    - duplicate mail entries for one cert
	    - emailaddress for certs with serialNumber and correct objectclass
	      stack
	    - new objectclass uniquelyIdentifiedUser from "Entrust Directory
	      Schema Requirements for Entrust 6.0"
	* removed encryption for mysql from OpenCA::DBI
2003-May-12:
	* second pre-release of 0.9.1.2
	* added Italian from Simone Rossi <simone.rossi@hp.com>
	* fixed a bug in the makefile of the ocspd in openca_0_9_1
	* OpenCA::X509 tolerates critical extensions
	* fixed errordetection for ldap updates of CA-certs (export-import.lib)
2003-Apr-28:
	* first pre-release of 0.9.1.2
	* added support for ldap servers which have more than one suffix
	* general bugfix for configuration from Ramon Llorens Creus
	  <rllorens@diputaciolleida.es>
	* bugfix for OpenCA::REQ (Ives Steglich <steglich@emt.iis.fhg.de>)
	* ldap code now schema compliant
	* added French from Nicolas Pouvesle <npouvesle@mond.net>
	* fixed generation of the serials
2003-Feb-23:
	* 0.9.1.1
	* OCSPd Correclty lookup using loaded CRL
	* OCSPd Added extensions management from CRL to OCSP response
	* OCSPd Updated the sample (contrib/) configuration file
	* OCSPd Added CRL retrivial from LDAP server
	* OCSPd Added LDAP support (needs OpenLDAP libraries)
	* OCSPd Added CRL retrivial from file
	* fixed SPKAC in basic_csr
	* fixed IE DNs in basic_csr
	* fixed export_import.lib
	* added patches from from Marc Pfatschbacher <pfatschi@gmx.net>
	    # basic_csr
	    # bpRevokeCertificate
	    # export-import.lib
	* fixed removeKey for DBM-files
	* fixed sign in OpenCA::OpenSSL (patch from Ramon Llorens Creus
	  <rllorens@diputaciolleida.es>)
2003-Jan-03:
	* 0.9.1
	* added TODO and CHANGES
2002-Dec-22:
	* 0.9.1 RC7
	* only openca.pot, openca-html.pot and the javascriptfiles must be
	  translated
	* language es_ES available
	* language de_DE to new mechanism migrated
	* fixed unclean usage of OpenCA::REQ in basic_csr and bpCreateCSR
	* several fixes for i18n (typos and wrong functions)
	* Javascript-fixes for Mozilla and Netscape <5
	* fixed several problems in OpenCA::DB
	* cleanup interface of OpenCA::DBI (DB2 works again) and avoid crashes
	  of the web interfaces if databases are down
	* fix for use of not unique DNs in crypto-utils.lib
	* don't overwrite mailcounter during importing mails
	* integrated security-fix of Microsoft for MS02-48
	* perl 5.8 supported
	* LDAP v3 supported
	* usercerts without emailaddress handled now correct by the ldap code
	* better signaturehandling for listReqs and viewSignature
	* added special CRL-generation
	* certificates cannot have a longer lifetime then the CA-cert now
	* PINs in the batchprocessors are now encrypted
	* fixed several missing statechecks
	* support for HSMs added (Chrysalis-ITS Luna CA3) - special thanks to
	  Bahaaldin Al-Amood <balamood@vt.edu>
	* new export/import system supports incremental exports
	* merged basic_csr, ie_req and spkac_req (incl. automatic browser
	  detection if wanted)
2002-Oct-02:
	* 0.9.1 RC6
	* fixed a bug in src/web-interfaces/pub/Makfile (download.cer installs now
	  correctly)
	* removed -lfl from ocspd/src/Makefile and openca-sv/src/Makefile
	* fixed DBI because MySQL is really sensitive for blanks between functions
	  and parenthesis
	* better references for scrolling certificates, CRLs and requests
	* port-option added to configure (this allow the usage of servers on
	  non-standardports)
	* use strict; in all webinterfaces
	* several modifications to support mod_perl
	* fixed signature-handling in approveCRR, approveCRRnotSigned,
	  changeCRR and listReqs
	* created csr-utils.lib
	* all cmds are now functions
	* several performance enhancements in OpenCA::REQ and OpenCA::X509 to
	  speedup lists
	* explicit commit and rollback for SQL-databases
	* i18n introduced including description in file I18N
	* language de_DE available
	* support for not unique DNs (patch for OpenSSL is available too)
	* fixed mail-setting in LDAP
	* fixed installation problem with keybackup_(key|cert).pem
2002-Sep-10:
	* 0.9.1 RC5
	* fixed typo in editCSR ($datatype --> $dataType)
	* fixed status bug in OpenCA::DBI (EXPIRED works now)
	* fixed serials in the DN (now the user see only decimal numbers)
	* rewrite the requestgeneration for IE because of some problems with
	  Siemens CardOS CSP
	* fixed the signatureverification
	* fixed import of CRR into CA
	* keybackup integrated into batchprocessor (still alpha)
	* structural cleanup completed
2002-Aug-29:
	* 0.9.1 RC4
	* renewCSR can handle now empty subject alternative names
	* certsMail.txt is now in the correct directory
	* fixed bug in crypto-utils.lib (now we can issue certificates from renewed
	  requests directly)
2002-Aug-28:
	* 0.9.1 RC3
	* RBAC:
		* deactivated debugging in rbac-utils.lib
		* removed conf-file for raServerInfo
		* added conf-file for serverInfo
		* security bugfix against misconfiguration of mod_ssl
		* some signatures will no longer used because they bring us
		  no additional security
	* RPM-specs updated (the binaries are now much smaller)
2002-Aug-23
	* 0.9.1 RC 2
	* IE-fixes:
		* getcert works again
		* download of certificates from other users via the pub-gw works
	* Win2000 smartcardlogin tested successfully (with patched OpenSSL)
2002-Aug-21
	* 0.9.1 RC 1
	* fixed src/Makefile for use without optional C-modules
	* fixed deleteCRR to make certificates valid if there are no other CRRs
	* several small Makefile-fixes
	* moved Makefile.crt into correct directory (causes crashes during make
	  install)
	* fixed bug in OpenCA::X509 (failed for DNs with attributes which
	  includes "/")
	* fixed wrong CDPs in ca-openssl.cnf, ra-openssl.cnf and
	  sample-openssl.ext.in
	* a small fix in mail-utils.lib
	* changePasswd fixed for OpenCA::DB
2002-Aug-15
	* several small changes
	* fixed CDPs in default-configuration
2002-Aug-14
	* new structure - ready for i18n and more productoriented (for re-use)
	* fixed signing for IE
	* fixed numbers of CRIN-mails
2002-Aug-12
	* 0.9.0
	* fixed typo in editCRR ($parsed --> $parsed_req)
	* fixed typo in approveCRR and approveCRRnotSigned ($req->getSerial -->
	  $cert->getSerial)
2002-Aug-09
	* RC 4
	* fix for systems with many users (linear list of links --> exponential
	  list of links)
	* OpenCA::DBI returns now 50 items and not 49 if listItems asks for 50 items
	* OpenCA::DBI start now with the first element of a list and not the
	  second one
	* you can download now keys which have the correct format for Apache's
	  mod_ssl
	* added navigation through the users of the batch processor (not an
	  official part of 0.9)
2002-Aug-05
	* RC 3
	* subject alternative name will be set automatically by default
	* signature handling for CSRs fixed
	* initialization for PostgreSQL fixed
	* log for PostgreSQL fixed
	* unused --prefix fixed
	* ldap-utils.lib creates the root-node of the directory now too
	* ldap-utils.lib is now caseinsensitive for DNs
2002-Jul-26
	* RC 2
	* fix for OpenCA::DBI
	* updated INSTALL, LICENSE, COPYRIGHT, README and HISTORY
	* added OpenCA-guide and lifecycle to the docs
2002-Jul-23
	* RC 1
2002-Jul-17
	* OpenCA::DBIS removed
	* spec-files updated (better versionnumbers for modules)
	* build-rpm.sh updated
2002-Jul-12
	* ARCHIVIED --> ARCHIVED
	* added link from viewCert to viewCSR
	* incompatible SQL DB-tables so follow the instructions in
	  SQL-DB-Format-Change (because we store the CSR's serial in the
	  request's header)
	* DBM-users has to make a backup before the installation and after the
	  installation they have to import this backup or do the following
		* cd openca_dir/var/db/
		* mv archivied_xyz archived_xyz
	* users can get their certificates via the CSR's serial and their ID from
	  the batchprocessors too
2002-Jul-11
	* genCRL fixed (creates now cacrl.(pem|der|crl|txt))
	* added the missing batchprocessors (nearly untested)
2002-Jul-05
	* fixed some problems with the signatureverification of requests
2002-Jul-04
	* forget to run autoconf (only users without autoconf was affected)
2002-Jul-03
	* better errormessages for genCAReq
2002-Jul-02
	* better errormessages for libIssueCertificate
	* another error 256 in OpenCA::OpenSSL
2002-Jul-01
	* fix a small bug in editCSR which causes the initialization to fail
	* include the first version of a batch processor
2002-Jun-24
	* better debuggingoutput for deleteCSR
	* fixed broken Makefile in src/cgi-bin/cgi-online/cmds/
	* support for full flexible CA-DNs
	* CRINs work
	* mailcounter will no longer be overwritten
2002-Jun-04
	* fix for changeCSR (yesterdays snapshot was broken)
2002-Jun-03
	* OpenCA works on Solaris
	* fixed broken ca.conf
2002-Jun-01
	* fixed problems with CA-certs and LDAP
2002-May-31
	* support for tokeninitialization on the RA
2002-May-30
	* support for renewal of requests
2002-May-27
	* fixes for mailsending
	* small fix for IE
2002-May-27
	* fix for IE
	* small fix for viewCRL
2002-May-24
	* RPMs are supported now
	* LDAP improvements
	* some changes in the organization of the sourcecode
	* several minor bugfixes
2002-Apr-29
	* full support for errno and errval in OpenCA::OpenSSL
	* getCRLAttribute added to OpenCA::OpenSSL
	* OpenCA::REQ fixed for parsing SPKAC-requests
	* convert issuer of OpenCA::X509 and OpenCA::CRL
	* OpenCA::OpenSSL detects errorcode 256 from OpenSSL and ignores it
	* some small fixes for better errordetection in export-import.lib
2002-Apr-23
	* several fixes for emailAddress
	* some fixes for rbac-utils.lib
	* CA Admin --> CA Operator
2002-Apr-19
	* we use DNs like described in RFC2253 only
	* the new module X500::DN and X500::RDN handles the conversion from RFC2253 and
	  X500 to OpenSSL
	* there is a new gateway for LDAP only
	* you must use an OpenSSL which includes the patches for the attribute emailAddress
	  (this require openssl-0.9.7-20020415 or higher)
2002-Apr-12
	* verifySignature works now with IE too
	* fixes for LDAP (objectcreation)
	* patch for FreeBSD from Nelson Murilo <nelson@pangeia.com.br>
	* fix for openca-verify from Alex
	* removed passphrases from the links (only using forms with POST and not GET)
2002-Apr-10
	* next fixes for the LDAP-code
	* fixes for PKCS#7 (verification is now faster because openca-verify
	  is only used once)
	* button for renew CSRs (but no background code because the format is not defined)
2002-Apr-09
	* all lists show the affected role
	* requests must not signed any longer
	* store LDAP-certs with other DN
	* update LDAP from viewCert directly
	* added an option to disable the automatic LDAP-update during import
	* several fixes for Javascript
2002-Apr-08
	* complete new names for RBAC (Base64 with small modifications)
	* change passphrase of private key fixed
	* fixed a bug in getItem of OpenCA::DB (CRRs should work now)
	* full support for IE (thanks to Alexandru and Marilena Matei)
	* fixed a bug in verifySignature on the pub-gw
	* some small fixes in OpenCA::OpenSSL
2002-Mar-28
	* several fixes for Solaris (see also configs/configure.michael_solaris)
2002-Mar-27
	* fixes for the export of certificates and keys
	* fixes for correct statehandling during revocation
	* fixed missing openssl-includes in OpenCA SV Tools
2002-Mar-22
	* some fixes to export/import
	* data and configuration will no longer be overwritten during installation
2002-Mar-21
	* several fixes for issueCertificate
	* more debugging output available for getSMIME in OpenCA::OpenSSL
	* all CRIN-mails in one directory
	* crashes with "Cannot encrypt PIN-mail!" caused by OpenSSL-snapshots
2002-Mar-15
	* UI-messages
	* issuing CRRs (several typos)
	* PKCS#12-export
2002-Mar-13
	* some fixes from Alexandre Matei
2002-Mar-12
	* the next fixes for getSerial
2002-Mar-11
	* fixed a lot of bugs related to getSerial
2002-Mar-08
	* several fixes (thanks to Alexandre Matei)
	* initialization works with OpenCA::DB too
2002-Mar-04
	* several fixes related to the new filesystem hierarchy
	* fix for IE requests
	* a lot of fixes for the new OCSP daemon
	* initialization works
2002-Feb-22
	* new filesystemhierarchy
	* headers of requests are signed too
	* this is a real testrelease because we changed over 100 files
	* download of certificates for IE should work
2002-Feb-18
	* fixed approveCSR
	* new installation code for the CA (experimental)
2002-Feb-15
	* standard user and group are configurable
2002-Feb-14
	* OpenCA::OpenSSL->sign has some more options
	* export-import.lib fixed (wrong code for installation of cacert.pem)
	* corrected some misspellings
2002-Feb-13
	* new script to generate requests
		* server-side generation of keypair
		* fully configurable via public.conf
		* support different configurations
	* better initialization
	* complete handling of private key on the RA
	* some improvements in the Makefiles
2002-Feb-05
	* several improvements related to configure
	* better initialization (you can simply use the web-interface)
	* one small bugfix for OpenCA::DB
	* configure still broken (exec-prefix must be set)
2002-Feb-04
	* better configure
	* fixes for DBM-files
	* some small bugfixes
	* configure broken (exec-prefix must be set)
2002-Jan-28
	* fix two bugs in the sheets for issuing and revoking certificates
2002-Jan-23
	* fixed a bug in OpenCA::DBI
2002-Jan-22
	* misc-utils.lib fixed
	* all files in lib/ are identical on CA, RAServer and Public
	* all files in cmds/ with the same name are identical on CA and RAServer
	* SCEP is no longer part of the installation (scheduled to v0.10)
2002-Jan-16
	* better UI for recovery
	* libraries are now idetically in ca, raserver and public
	* remove the CRL-state EXPIRED (CRLs never expiring)
2002-Jan-15
	* several small fixes
	* ldap can handle sn now
	* recovery fixed again
	* approval of CSRs works now
	* approval of CRRs works now
	* add userCertificate to LDAP fixed
2002-Jan-12
	* fixes
2002-Jan-11
	* fix file-permissions of the RBAC-configuration
	* complete update of the RBAC-configuration
	* add the role Mail Server
2002-Jan-10
	* many bugfixes because of the new code for CSRs and CRRs
	* since 2001-Dec-20 the recovery-code for index.txt and serial was broken (fixed)
	* OpenCA::OpenSSL has two new functions - getOpenSSLDate and getNumericDate
	* fixed the Makefile of cgi-public/sheets/
	* OpenCA::DBI handles now expired certs automatically (an expired cert is not a valid cert)
	* incompatible SQL DB-tables so follow the instructions in SQL-DB-Format-Change
	  (because of the correct handling of expired certs)
2002-Jan-09
	* added some missing files for OpenCA::DB (thanks to chris crowley)
	* complete new organization of the code for approving a request (CSRs and CRRs)
	* this snap has many bugs because the code for approving requests is not tested
	  (so this snapshot is not recommended for non-developers)
	* if Req means only CSR then *Req(|s) -> *CSR
2002-Jan-08
	* some fixes to support Mozilla which has some bugs
2002-Jan-04
	* Oracle improvements again
	* incompatible SQL DB-tables so follow the instructions in SQL-DB-Format-Change
2002-Jan-03
	* CRR improvements
	* Oracle support
	* incompatible SQL DB-tables so follow the instructions in SQL-DB-Format-Change
2001-Dec-22
	* sendmail integrated into configure.in
	* several improvements for CRIN-mails
2001-Dec-21
	* send CRIN-mails
	* some small fixes on the CA
	* better support for subjectAltName
	* displays correct DN and subjectAltName on CA and RAServer
2001-Dec-20
	* small fixes in OpenCA:OpenSSL (missing -config option)
	* first fixes for PIN-Mails
	* in OpenCA exists only decimal numbers
	* OpenCA::CRL and OpenCA::X509 fixing the certificate's serial
2001-Dec-19
	* import of CRLs works completely
	* ie_req should work now
	* correct initialization of OpenCA::OpenSSL
	* LDAP-code fixed
2001-Dec-18
	* because of a corruption of my cvs-files, this snap is highly
          recommended
	* fixes a Javascriptproblem for genCAReq (creates the CA's request)
        * fixes the crl-links on the Public-GW
        * fixes export-import-code again (more robust, bugs easier to find
          and fix)
        * export/import of CRLs works (still a problem with the installation
          of the CRL-directory on Public-GW)
2001-Dec-17
	* fixed two files which are perhaps corrupted in the last snap
2001-Dec-15
	* CRRs on the RAServer works completely
	* export/import of CRRs
	* CRRs on the CA
	* new design of the main-page (CA)
	* issuing CRL works (only tested nothing to do)
	* recovery of OpenSSL's index.txt works (tested with CRRs)
2001-Dec-14
	* new design of the main-page (RAServer)
	* CRRs on the RAServer
2001-Dec-13
	* CRRs on the Public-GW
	* new design of the main-page (Public-GW)
	* command "lists" works
2001-Dec-12
	* fixed Makefiles of OpenSCEP
2001-Dec-10
	* OpenSCEP included
2001-Dec-01
	* initial OpenCA v0.9 snapshot

SQL-DB-Format-Change
--------------------
	# still use your old snapshots
	# exportDB via the link on the input/output-page (Backup)
	# destroy your database
	# make a backup of the CA's private key and cert (by hand)
	# install new snapshot
	# install the backup of the CA's private key and cert (by hand)
	# initialize your database again via the link on the input/output-page (Recovery)
	# replayLog via the link on the input/output-page (Recovery)

